Manifesto
SecOpsAI connects network discovery, software supply-chain monitoring, host and agent telemetry, findings triage, research evidence, and reporting. These documents follow the same operating sequence from collection and detection through investigation, remediation, disclosure, and publication.
Core guides
Follow the product workflow in operating order.
Start with deployment and data collection. Continue through findings, research, and reporting. Use the reference material when you integrate or scale the platform.
Getting Started
Install SecOpsAI, activate the virtual environment, and run the first local pipeline.
Guide 02SecOpsAI Edge
Register a sensor, discover authorized networks, synchronize the asset graph, and operate scheduled scans safely.
Guide 03Findings Triage
Review evidence, assign status and disposition, record notes, and verify remediation with a repeatable analyst workflow.
Guide 04Research Discovery
Configure cross-ecosystem watchlists, registry monitors, candidate scoring, package comparison, and campaign correlation.
Guide 05Research Cases
Manage evidence, IOCs, verdicts, sandbox approval, responsible disclosure, publication safety, and case monitoring.
Guide 06Deployment Guide
Choose local, sensor, hosted-pilot, and service-provider deployment patterns with clear security boundaries.
Capabilities
Documentation for each operating surface.
The information architecture follows product ownership: collection, investigation, research, response, publication, and deployment.
Discover and collect
Collect Edge network observations, host telemetry, and local automation state without sending raw telemetry to a central SIEM.
Triage and investigate
Move findings and package candidates through evidence-backed review, research cases, and explicit analyst decisions.
Operate and publish
Apply rules, deploy services, export intelligence, and publish reviewed research through approval-gated workflows.
Quick Start
Deploy in minutes.
Install Core, collect local telemetry, correlate findings, and open the operator workflow from one command sequence.
# Install and initialize
curl -fsSL https://secopsai.dev/install.sh | bash
cd ~/secopsai
source .venv/bin/activate
secopsai refresh
secopsai refresh --platform macos,openclaw,hermes
secopsai correlate
secopsai triage orchestrate --search-root ~/secopsai
SecOpsAI Core
Canonical findings, graph, triage, research, correlation, and reporting store.
SecOpsAI Edge
Authorized asset discovery, service exposure, Wi-Fi inventory, and sensor jobs.
SecOpsAI Research
Registry monitoring, candidate scoring, evidence, disclosure, and publication gates.
OpenClaw
Local automation bridge for approved Core and Edge operator actions.
Host adapters
macOS, Linux, Windows, and Hermes telemetry adapters with platform-specific coverage.
Contact
Reach the SecOpsAI team.
Use the right channel for security reports, independent research, disclosure coordination, or research collaboration.